Description
WordPress Plugin Woo Import Export is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin Woo Import Export version 1.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
http://lenonleite.com.br/en/publish-exploits/english-plugin-woo-import-export-1-0-rce-unlink/
https://www.exploit-db.com/exploits/44520/
https://wordpress.org/plugins/woo-import-export-lite/#description
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5317)
Drupal Core Cross-Site Scripting (8.0.0 - 9.1.15)
WebLogic Incorrect Authorization Vulnerability (CVE-2018-1258)
WordPress Plugin WP Google Maps Cross-Site Scripting (7.10.41)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2009-0033)